Colorado 2026 Regular Session

Colorado Senate Bill SB26185

Caption

Concerning measures to enhance the office of information technology's security procedures.

Summary

SB26-185 makes a series of changes to Colorado law governing the Office of Information Technology (OIT) and the chief information security officer (CISO) to strengthen oversight, reporting, and security governance. The bill gives the Joint Technology Committee (JTC) authority to call the CISO to testify on the required compliance report and, under specified conditions, to request that the Legislative Audit Committee direct a special information technology security audit of OIT. Those conditions include unresolved state auditor recommendations that are more than two years past their implementation date or a material discrepancy between a compliance report and a prior audit finding. The bill also requires OIT to maintain and share a quarterly updated inventory of active information technology vendor contracts for state agencies, including vendor name, contract value, expiration date, and data classification/business criticality tier. It restricts OIT from publishing or implementing technical information technology standards unless they are publicly posted and, when related to security, access controls, or data handling, approved by the CISO; emergency standards may be implemented immediately but expire after 90 days unless formalized. In addition, OIT must ensure contracts providing ongoing service and delivery to Coloradans keep current architecture diagrams updated at least annually, and the chief information officer may not delegate any duty, responsibility, or power of the CISO.

Impact

The bill amends several sections of the Colorado Revised Statutes, including provisions on the powers of the Joint Technology Committee, the roles and responsibilities of OIT, delegation authority, and the duties of the chief information security officer. It creates new annual reporting requirements for the CISO, including a statewide information technology security compliance report and a statewide security risk report, and authorizes security evaluations such as penetration testing and vulnerability scanning. It also requires state agencies to provide access and information needed for those evaluations and makes the CISO responsible for the accuracy of the reports. If a special audit is ordered, OIT must reimburse the state auditor, potentially using the Technology Risk Prevention and Response Fund.

Sentiment

The available context suggests generally favorable or at least bipartisan support for the bill’s goal of improving cybersecurity oversight and accountability, as reflected in its advancement and final enactment. The bill’s sponsors include members from both parties, which indicates cross-party interest in strengthening state IT security procedures. No committee transcript or recorded vote details were provided, so there is no evidence in the record supplied here of organized opposition or divided sentiment.

Contention

The main points of contention implied by the bill text are institutional control and transparency. The bill increases legislative oversight of OIT by allowing the JTC to trigger a special audit and by requiring more detailed reporting on compliance, unresolved audit findings, and statewide security risk. It also limits OIT’s discretion by requiring public posting and CISO approval for certain technical standards, prohibiting delegation of CISO powers, and mandating that agencies provide system access and architecture information for security evaluations. These provisions could be viewed as strengthening accountability, but they also impose additional administrative burdens and may raise concerns within OIT and state agencies about workload, operational flexibility, and the cost of audits and reporting.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.